We are seeking an experienced Security Architect to define and implement a comprehensive cloud security framework and architecture that aligns with business requirements and performance objectives. This role involves documenting cloud security controls and facilitating the transition to cloud security-managed operations. The ideal candidate will have a strong background in Application Security Architecture and Design, with at least 7.5 years of relevant experience and a minimum of 15 years of full-time education.
Key Responsibilities:
- Perform threat modeling and conduct security reviews of AI features, including large language model (LLM) enabled applications, retrieval augmented generation (RAG) systems, inference pipelines, and agentic workflows.
- Identify AI-specific attack surfaces such as prompt injection, insecure output handling, sensitive data exposure, excessive agency, and supply chain risks, and drive mitigation efforts to completion.
- Assess security and privacy risks associated with third-party AI vendors, foundation models, configurations, and machine learning libraries in collaboration with governance teams.
- Design and execute red team exercises targeting internal AI systems, focusing on scenarios like prompt injection, jailbreaks, model extraction, data poisoning, and tool or agent abuse.
- Document findings, reproduce failure modes, and work closely with engineering teams to implement robust fixes.
- Continuously update adversarial test cases to reflect changes in models, prompts, and deployment architectures.
- Define and maintain secure-by-default patterns for prompt construction, tool usage, retrieval, output handling, and model deployment.
- Mitigate risks unique to agentic systems where LLM outputs interact directly with shell commands, database queries, or multi-cloud platform parameters by establishing trust boundaries, input/output validation, and enforcing least privilege access.
- Publish and maintain reference implementations and guardrail libraries for easy adoption by engineering teams.
- Develop automated AI security tooling evaluation harnesses, including guardrail testing, model scanning, and prompt scanning, integrating these into CI/CD pipelines.
- Instrument CI/CD pipelines to detect insecure prompt patterns, over-permissioned tool configurations, and policy violations prior to production deployment.
- Evaluate and adopt relevant open-source and commercial AI security tools such as Garak, PyRIT, and Promptfoo.
- Collaborate with product and information security teams on detection, containment, and post-incident reviews related to AI security events.
- Act as a subject matter expert during AI security incidents, providing rapid triage and root cause analysis.
- Contribute to internal AI usage policies and secure development guidelines, ensuring alignment with current threat intelligence and practical application for engineering teams.
- Coach product and machine learning engineers on safe AI development practices through design reviews, office hours, and training materials.
- Monitor the evolving AI threat landscape, including frameworks like OWASP LLM Top 10, MITRE ATLAS, and NIST AI RMF, translating new insights into prioritized, actionable controls.
Required Qualifications:
- Minimum of 7.5 years of experience in Application Security Architecture and Design, with a demonstrated hands-on focus on AI/ML security.
- Proven expertise in assessing LLM-based applications for vulnerabilities such as prompt injection, insecure output handling, sensitive data exposure, and excessive agency.
- Proficiency in Python for building security automation, evaluation scripts, and prototyping tooling.
- Working knowledge of modern AI/ML technology stacks, including APIs from OpenAI or Anthropic, LangChain or LlamaIndex frameworks, vector databases, and at least one major cloud platform.
- Familiarity with AI security frameworks such as OWASP LLM Top 10, MITRE ATLAS, or NIST AI Risk Management Framework.
- Educational background comprising 15 years of full-time education.
Preferred Qualifications and Additional Information:
- This position is based in Hyderabad.
- While no additional preferred skills are specified, candidates with a strong passion for AI security and a proactive approach to emerging threats will excel in this role.
This role offers the opportunity to work at the forefront of AI security, combining offensive research, defensive engineering, and policy development to ensure the safe and responsible deployment of AI-powered features.